documentation-lookup

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves documentation from an external service and incorporates it into the agent's context, creating a surface where malicious or manipulated documentation could attempt to influence the agent's behavior.
  • Ingestion points: User queries and documentation snippets fetched via the resolve-library-id and query-docs MCP tools (SKILL.md).
  • Boundary markers: None explicitly defined to isolate or neutralize the external documentation snippets.
  • Capability inventory: Network access through platform-configured MCP tools (SKILL.md).
  • Sanitization: The skill mandates redacting secrets from queries, but does not provide instructions for sanitizing the documentation returned from the external service.
  • [DATA_EXFILTRATION]: The skill transmits user-provided questions to the external Context7 documentation service, which constitutes a network operation to a non-whitelisted domain.
  • Evidence: User questions are used as the 'query' parameter for external tool calls to improve document relevance (SKILL.md).
  • Mitigation: The skill includes a clear 'No sensitive data' directive, instructing the agent to redact API keys, passwords, and tokens before they are sent to the external service.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — documentation-lookup